CVE-2024-9798

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-9798
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9798.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9798
Published
2024-10-10T08:15:04Z
Modified
2025-10-22T07:54:37.308697Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.

References

Affected packages

Git / github.com/zowe/api-layer

Affected ranges

Type
GIT
Repo
https://github.com/zowe/api-layer
Events

Affected versions

Zowe_1.*

Zowe_1.11.0
Zowe_1.12.0
Zowe_1.13.0
Zowe_1.14.0
Zowe_1.15.0
Zowe_1.16.0
Zowe_1.17.0
Zowe_1.18.0
Zowe_1.19.0
Zowe_1.20.0
Zowe_1.21.1
Zowe_1.22.0
Zowe_1.23.0
Zowe_1.24.0
Zowe_1.25.0
Zowe_1.26.0
Zowe_1.27.0
Zowe_1.28.0

v0.*

v0.0.25

v1.*

v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.10
v1.1.11
v1.1.12
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7
v1.1.8
v1.1.9
v1.11.0
v1.12.0
v1.12.1
v1.12.2
v1.13.0
v1.14.0
v1.15.0
v1.16.0
v1.17.0
v1.17.1
v1.18.0
v1.18.1
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.20.0
v1.20.1
v1.20.10
v1.20.14
v1.20.15
v1.20.16
v1.20.18
v1.20.19
v1.21.10
v1.21.11
v1.21.12
v1.21.13
v1.21.2
v1.21.3
v1.21.4
v1.21.5
v1.21.6
v1.21.8
v1.21.9
v1.22.0
v1.22.1
v1.22.2
v1.22.3
v1.22.4
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.23.4
v1.23.5
v1.23.6
v1.23.7
v1.23.8
v1.24.0
v1.24.2
v1.24.3
v1.24.4
v1.24.5
v1.24.6
v1.24.7
v1.25.0
v1.25.1
v1.25.2
v1.25.3
v1.25.4
v1.25.5
v1.25.6
v1.25.7
v1.26.0
v1.26.1
v1.26.13
v1.26.15
v1.26.16
v1.26.17
v1.26.18
v1.26.19
v1.26.2
v1.26.20
v1.26.3
v1.26.4
v1.26.5
v1.26.6
v1.26.7
v1.26.8
v1.26.9
v1.27.11
v1.27.13
v1.27.15
v1.27.16
v1.27.17
v1.27.18
v1.27.19
v1.27.2
v1.27.20
v1.27.21
v1.27.22
v1.27.23
v1.27.24
v1.27.25
v1.27.26
v1.27.3
v1.27.4
v1.27.5
v1.28.0
v1.28.1
v1.28.2
v1.28.3
v1.28.4
v1.28.5
v1.28.6
v1.28.7
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.4.0
v1.4.1
v1.4.2
v1.6.0
v1.7.0

Other

v11